// DAILY INTELLIGENCE FEED · MSP & HELPDESK
ARCHIVEBLOGSUBSCRIBE FREE →
← back to archive
// ARCHIVED ISSUE

Thursday, September 10, 2026

1 CRITICAL4 WARNING7 storiesin𝕏
// FROM THE FLOOR
RISK_LEVEL: 🔴 HIGH

Prioritize patching CVE-2026-85880 and the SQL Server RCEs on all production systems before end of business today — don't wait for Tuesday testing cycles.

// full analysis + daily context delivered to subscribers → subscribe free
☁️ M365/AZURE2 items
WARNING☁️ M365/Azure

Microsoft 365 Reportedly Down Again for Some Users — September 8, 2026

User reports of Microsoft 365 service disruption surged on DownDetector around 8:12 AM ET on September 8, just days after the resolution of the Sep 1–3 outage. The scope and cause have not yet been formally confirmed by Microsoft. MSPs should monitor the M365 Status Twitter account (@MSFT365Status) and the Service Health Dashboard in the Admin Center for real-time updates.

Read more →
WARNING☁️ M365/Azure

M365 Search Broken in SharePoint Online, OneDrive, Outlook Web & Desktop — Ongoing Reports

Users in multiple regions continue to report an inability to search for content across SharePoint Online, OneDrive, Outlook on the web, and Outlook desktop. Additionally, users in Japan have reported access issues affecting Teams and M365 broadly. Check Microsoft's Service Health Dashboard under your Admin Center for your tenant's specific incident ID.

Read more →
🔐 SECURITY2 items
CRITICAL🔐 Security

CVE-2026-85880: Windows ALPC Zero-Day EoP — Actively Exploited, Patch Now

CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) component, allowing a low-privilege AppContainer attacker to escape the sandbox and gain SYSTEM privileges with no user interaction required. Microsoft confirmed active exploitation in the wild prior to the patch being issued. Apply the September 2026 Patch Tuesday update immediately; no workaround is available — patching is the only remediation.

Read more →
WARNING🔐 Security

September Patch Tuesday Includes Four Critical SQL Server RCEs — Database Servers at Risk

Four critical remote code execution vulnerabilities affect Microsoft SQL Server in the September 2026 update, with databases often carrying sensitive business data and having privileged access to adjacent systems. September's release also patched 9 CVEs in Exchange Server and 16 in SharePoint Server. Apply the SQL Server cumulative update before end of week for any externally or internally accessible SQL instances.

Read more →
🔥 NETWORKING1 item
WARNING🔥 Networking

Windows Kerberos RCE (CVE-2026-69676, CVSS 8.8) — Capture-Replay Attack, 'Exploitation More Likely'

CVE-2026-69676 is a critical RCE vulnerability in Windows Kerberos (CVSS 8.8) that allows a low-privilege attacker to exploit an authentication bypass via capture-replay techniques to execute arbitrary code. Microsoft rates this as 'Exploitation More Likely,' making it a priority patch for any environment with domain controllers or Kerberos-dependent services. Also patch Windows RRAS (CVE-2026-69590, CVE-2026-72950, CVE-2026-72959, CVE-2026-69852) on internet-facing or VPN-adjacent systems.

Read more →
🤖 AI/TOOLING1 item
INFO🤖 AI/Tooling

ConnectWise Sidekick Expanding AI-Assisted Ticket Triage and Documentation in 2026

ConnectWise Sidekick, embedded in the ConnectWise ecosystem, is gaining adoption for AI-driven ticket summarisation, response drafting, and documentation reduction — targeting the documented reality that labour represents 50–60% of MSP costs. Early data from MSPBots, a competing platform, shows up to 80% less dispatcher time and 23% faster SLA resolution through AI-driven workflow optimisation. MSPs evaluating AI service-desk tooling should pilot one platform against a defined ticket category before broad rollout.

Read more →
📡 INDUSTRY1 item
INFO📡 Industry

ASIC Regulatory Strategy Update — September 2026 Parliamentary Testimony Has Compliance Implications for Fintech and MSP Clients

ASIC Chair Sarah Court's September 4 statement to the Parliamentary Joint Committee flagged a new Statement of Expectations requiring ASIC to weigh regulatory impact on small business and new entrants, alongside five updated priorities from the Corporate Plan 2026–27. MSPs serving financial services clients should review the updated ASIC Corporate Plan to identify any new cybersecurity, data handling, or reporting obligations affecting those clients. The full hearing transcript is available via the Parliamentary committee website.

Read more →
Wednesday, September 9, 2026
Friday, September 11, 2026
// this lands in your inbox every weekday

This is what you get — every weekday, free.

Subscribers get the full “From the Floor” take with every issue — not just the news summary you just read.
Written from 12 years on the helpdesk floor. Always free.

// no spam · every weekday morning · unsubscribe anytime

LATESTARCHIVEBLOGSUBSCRIBE

// AI-assisted · always verify before acting · not professional security advice